Bug 1598581 (CVE-2018-10892)

Summary: CVE-2018-10892 docker: container breakout without selinux in enforcing mode
Product: [Other] Security Response Reporter: Laura Pardo <lpardo>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: abhgupta, adimania, admiller, ahardin, amurdaca, andreas.bierfert, bbaude, bleanhar, ccoleman, dbaker, ddarrah, dedgar, dominik.mierzejewski, dornelas, dwalsh, gmollett, ichavero, jcajka, jchaloup, jgoulding, jligon, jnovy, jokerman, jshepherd, lsm5, lsu, marianne, mchappel, mheon, nalin, santiago, sthangav, trankin, tsweeney, umohnani, vbatts
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
The default OCI Linux spec in oci/defaults{_linux}.go in Docker/Moby, from 1.11 to current, does not block /proc/acpi pathnames. The flaw allows an attacker to modify host's hardware like enabling/disabling Bluetooth or turning up/down keyboard brightness.
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-06-10 10:32:01 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1598582, 1598583, 1598584, 1598585, 1598630, 1599130, 1599131, 1599132, 1599133, 1599134, 1599135    
Bug Blocks: 1598588    

Description Laura Pardo 2018-07-05 21:53:24 UTC
The deafult OCI linux spec in oci/defaults{_linux}.go in Docker/Moby
from 1.11 to current does not block /proc/acpi pathnames. The flaw allows an attacker to modify host's hardware like enabling/disabling
bluetooth or turning up/down keyboard brightness.

Comment 1 Laura Pardo 2018-07-05 21:54:42 UTC
Created docker tracking bugs for this issue:

Affects: epel-6 [bug 1598585]
Affects: fedora-all [bug 1598583]


Created docker-latest tracking bugs for this issue:

Affects: fedora-all [bug 1598582]

Comment 3 Antonio Murdaca 2018-07-05 23:02:20 UTC
I already have a fix for upstream and downstream docker.

Comment 6 Jason Shepherd 2018-07-06 03:29:11 UTC
Acknowledgments:

Name: Antonio Murdaca (Red Hat)

Comment 8 Antonio Murdaca 2018-07-06 10:08:54 UTC
Upstream fix is here https://github.com/moby/moby/pull/37404

Comment 9 Antonio Murdaca 2018-07-06 11:07:04 UTC
Our projectatomoic/docker downstream fork has been fixed as well.

Comment 10 Trevor Jay 2018-07-07 05:54:22 UTC
The tracking and other problems surrounding this issue are entirely my fault. I thought of this more as an OCI/compliance issue and directly went against Red Hat policy on upstream disclosure. It was my *wrong* call. If there's any remaining loose ends from that fallout, please let me know.

I think we are tracking correctly now (special thanks to everyone who got cri-o marked affected especially).  Like I said: if anything else has fallen between the cracks, let me know so I can get some grout.

_Trevor

Comment 11 Jason Shepherd 2018-07-09 03:13:54 UTC
Created cri-o tracking bugs for this issue:

Affects: fedora-all [bug 1599131]


Created podman tracking bugs for this issue:

Affects: fedora-all [bug 1599130]

Comment 13 Jason Shepherd 2018-07-09 03:14:27 UTC
Created cri-o tracking bugs for this issue:

Affects: fedora-all [bug 1599135]


Created podman tracking bugs for this issue:

Affects: fedora-all [bug 1599134]

Comment 17 Ed Santiago 2018-08-09 13:40:13 UTC
Is it too late to fix a typo? Should be "default"

Comment 18 Lokesh Mandvekar 2018-08-09 13:42:46 UTC
(In reply to Ed Santiago from comment #17)
> Is it too late to fix a typo? Should be "default"

Nope, thanks for pointing out. Maxim, typo fixed in Doc Text 'cause' field.

Comment 20 errata-xmlrpc 2018-08-16 16:05:40 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extras

Via RHSA-2018:2482 https://access.redhat.com/errata/RHSA-2018:2482